- Deployment
- Self-hosted, in your own infrastructure.
- Tenancy
- Multi-tenant. Isolation is enforced at the query layer on every read and write, and fails closed.
- Identity
- OpenID Connect SSO per tenant, plus local accounts with bcrypt hashing, brute-force lockout and instant session revocation.
- Access control
- Seven roles, from super admin to read-only viewer, with a permission check on every endpoint. Analysts can be granted several tenants.
- Ingestion
- REST API and webhooks with tenant-scoped keys. Severity normalization and deduplication by alarm id.
- Sources
- SIEM, EDR and XDR, NDR, network monitoring, perimeter and firewalls, email security, threat intelligence feeds, identity, ticketing and ITSM.
- Automation
- Tenant-authored Python playbooks in ephemeral, non-root containers with a restricted network.
- AI enrichment
- Optional and on demand, through the AI integration you configure. Output is validated and never executed.
- Reporting
- Branded PDF per tenant and period with alarm and incident statistics, MTTA and MTTR.
- Monitoring
- DMARC aggregate reports, TLS certificate expiry, allow and block IP lists served as plain-text feeds.
- Audit
- Per-tenant audit trail of logins, changes and list edits.